What Property Managers Need to Know About Cyber Threats: Lessons from IHM 2026

By Telelink

Every day, property management teams handle deeply personal information, from banking details and identification to payment records, accommodation needs and building access information.  

While that information is essential to serving residents, it also makes the industry an attractive target for cybercriminals. 

Now add resident portals, smart building systems and connected technology to the mix.  The result is easier, more efficient operations, but also more points of vulnerability to manage. 

With global cybercrime costs estimated at US$10.5 trillion a year and the average data breach costing about US$4.44 million, cybersecurity is becoming an operational issue that needs to stay front and centre. 

At the Institute of Housing Management (IHM) Conference 2026, cybersecurity expert Cyrus Wang summed up the challenge simply: the question is no longer whether your organization will face a cyber incident, but whether you'll be ready when it happens. 

Here are five practical takeaways from that IHM session that property management teams should sit with. 

1. The easiest way in is through a trusted person 

The obvious phishing email from an unknown sender, complete with suspicious links and bad grammar, is no longer the only thing teams need to watch for. 

Today's attacks often come from compromised accounts belonging to people you actually know. Attackers map out relationships, use AI to write convincing messages, clone voices and even stage deepfake video meetings. 

Cyrus Wang, Manager of Information Security with the Regional Municipality of Durham, put the underlying risk simply: many attacks succeed because someone clicked, approved, transferred or trusted something they shouldn't have. 

In property management, that could look like an email from a long-time contractor asking you to update their banking information before the next payment. Or a phone call that sounds exactly like a senior leader asking for an urgent transfer. A few years ago, neither might have raised an eyebrow. Today, they should. 
 
A firewall can only do so much. When attacks rely on trust, urgency or impersonation, a prepared team becomes just as important. 

That means regular training, phishing exercises, deepfake awareness and a culture where staff feel comfortable pausing to verify a request, even when it appears to come from the top. 

2. Buildings are getting smarter, and so are the risks 

Some cyber threats are designed to stay hidden. 

Info-stealer malware, for example, can quietly collect passwords, browser credentials and session tokens without locking files or disrupting a system. In some cases, it can even delete itself afterwards. Everything may look completely normal while stolen credentials are being sold or misused elsewhere. 

Then there are the systems inside the building itself. 

HVAC controls, access systems, smart locks, cameras, sensors and building automation platforms can all create additional points of entry. Many of these systems remain in service for years, sometimes running older software or receiving security updates less frequently. 

That makes a few simple questions worth asking contractors or technology providers with access to your systems: How is that access secured? Who can get in? How often is the system updated? What happens if that access is compromised? 

3. The basics still do the heavy lifting 

Cybersecurity can sound complicated, but some of the most important protections are surprisingly foundational. The session highlighted: 

  • Multi-factor authentication on every account that supports it 
  • Regular patching and endpoint protection across devices 
  • Frequent backups and ongoing security monitoring 
  • Clear security requirements for vendors 

For property management teams, these are the controls that help reduce everyday risk across the systems staff rely on. 
 
Backups deserve particular attention. If ransomware encrypts your files or a system becomes unavailable, having a recent, working backup can make a significant difference to how quickly your team can recover and resume operations. 

There are insurance implications too. Cyber insurers increasingly expect organizations to have basic safeguards in place, and missing controls can affect premiums, coverage or claims. 

The takeaway isn't that every property management company needs to become a cybersecurity company. It's that the basics shouldn't be optional. 

4. Build your response plan before you need it 

A cyber incident is a terrible time to start deciding who should do what. The session emphasized how organizations can lose weeks, even months, simply figuring out who to call, what needs to happen next, and who is responsible for making decisions. 

For property management teams, that means having those answers before there is a problem. 

Know who your legal contact is, who to call at your insurer, which incident response provider you'll use and where forensic support will come from. Make sure staff know how to escalate something suspicious and who needs to be notified internally. 

Some cyber insurance policies may also require notification within as little as 48 hours. If your team is still trying to work out the process after an incident starts, valuable time may already be lost. 
And recovery isn't only about restoring systems. How quickly and clearly you communicate with residents, clients and staff can shape how much trust is preserved during the disruption. 
 

5. Know how long you can run without your systems 

Two questions every property management team should be able to answer: 

How long can we operate without our systems? That's your Recovery Time Objective. It could be 24 hours, a week or two weeks, but it should be a number you've decided on, not one you discover mid-crisis. 

How much data can we afford to lose? That's your Recovery Point Objective. If your last backup ran at 8 p.m. and an incident happens at 8 a.m., that could be 12 hours of rent payments, work orders and resident notes to rebuild. 

This is also where business continuity planning becomes practical. 

Cyrus pointed out that many plans are too old, too complex or never tested. Key people have moved on, processes have changed and documentation hasn't kept up. 

A useful continuity plan should reflect how your team operates today and get tested regularly. It should also spell out realistic workarounds, from spare laptops and spreadsheet tracking to manual rent processing, maintenance tracking, and resident communication. 

The goal is simple: know how your team will keep operating while systems are being restored. 

Staying connected with residents, no matter what 

Property management doesn’t stop in the middle of a disruption, and resident concerns and maintenance requests can’t be perfectly timed. 

That’s why staying reachable is part of business continuity, and it’s one area Telelink can help support while your team focuses on getting systems and operations back on track. 

Organizations that recover best aren't always the ones that avoid every attack. They're the ones that train their people, secure their systems, test their plans, and prepare for the possibility that something could get through. If you're updating your continuity plan and want to talk through where resident communication fits in, we'd love to connect. 

Please note: Telelink is not a property management company or cybersecurity expert. Telelink is a 24/7 call centre that specializes in servicing the property management industry. The opinions expressed in this article reflect our experience supporting property management and affordable housing organizations across Canada, along with insights shared by Cyrus Wang at the 2026 IHM conference. This content is not intended as regulatory or compliance guidance. 

Get started today.

You'll be surprised how quick and easy it is to get up and running with Telelink answering services.

Details and Pricing

Talk to Us